CVE-2026-73807
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mySCADA Technologies | mySCADA myPRO | 0 <= 2.1 | affected |
| mySCADA Technologies | mySCADA myPRO | 2.2 | unaffected |
Weaknesses
- CWE-862: CWE-862
References
- https://www.myscada.org/downloads/mySCADAPROManager/
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-258-03
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-258-03.json
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.